1
00:00:01,390 --> 00:00:03,910
Hello and welcome to the sixth lecture.

2
00:00:03,910 --> 00:00:06,220
By now, you've seen a lot
of the basics of Bitcoin,

3
00:00:06,220 --> 00:00:11,600
how the system works, how mining works,
and how to use Bitcoin as a currency.

4
00:00:11,600 --> 00:00:15,630
Now let's get to what has been one of
the most controversial aspects of Bitcoin,

5
00:00:15,630 --> 00:00:18,400
which is the anonymity
properties of Bitcoin.

6
00:00:18,400 --> 00:00:21,060
And in fact,
there's a lot about Bitcoin and

7
00:00:21,060 --> 00:00:23,550
anonymity that you'll hear
different opinions on.

8
00:00:23,550 --> 00:00:25,910
Is Bitcoin anonymous, first of all?

9
00:00:25,910 --> 00:00:28,390
Are anonymous cryptocurrencies
even a good thing?

10
00:00:28,390 --> 00:00:30,850
Is it good for
people who have a stake in Bitcoin?

11
00:00:30,850 --> 00:00:32,620
Is it good for society?

12
00:00:32,620 --> 00:00:34,170
And what is the various,

13
00:00:34,170 --> 00:00:37,069
various proposals that have been
made to improve BItcoin's anonymity?

14
00:00:38,120 --> 00:00:41,500
How well do those work,
which of those should we adopt, and so on.

15
00:00:41,500 --> 00:00:46,320
So in this lecture what we're going to do
is help cut through all of that confusion

16
00:00:46,320 --> 00:00:50,610
and we're going to discuss where
things are, what are the options, and

17
00:00:50,610 --> 00:00:52,550
where things seem to be going..

18
00:00:52,550 --> 00:00:53,650
So let's start like this.

19
00:00:53,650 --> 00:00:57,980
Let's start with the basic understanding
of what we even mean when we say

20
00:00:57,980 --> 00:01:01,270
anonymity in Bitcoin, and
some of the overall concepts like

21
00:01:01,270 --> 00:01:04,780
how does anonymity tie in to privacy,
is that a good thing or a bad thing?

22
00:01:04,780 --> 00:01:07,980
Can we only have the good aspects
of anonymity without the bad?

23
00:01:07,980 --> 00:01:10,030
A variety of questions like that.

24
00:01:10,030 --> 00:01:13,950
And then we'll see a variety of proposals,
some already existing and

25
00:01:13,950 --> 00:01:16,630
some that may be implemented some day.

26
00:01:16,630 --> 00:01:18,660
For improving Bitcoin's anonymity, or

27
00:01:18,660 --> 00:01:21,875
creating different anonymous
cryptic currencies altogether.

28
00:01:21,875 --> 00:01:26,040
And And what's interesting about
them is that they offer a variety

29
00:01:26,040 --> 00:01:30,330
of increasing levels of cryptographic
sophistication, as we go down this list.

30
00:01:30,330 --> 00:01:35,700
And we'll learn to see what the tradeoffs
are, and analyze the anonymity properties.

31
00:01:35,700 --> 00:01:37,190
How deployable these are, and so on.

32
00:01:38,660 --> 00:01:39,230
All right.

33
00:01:39,230 --> 00:01:40,760
Let's get started.

34
00:01:40,760 --> 00:01:43,640
If you look online, you'll see that
there are a number of people in

35
00:01:43,640 --> 00:01:45,610
groups saying that Bitcoin is anonymous.

36
00:01:45,610 --> 00:01:48,260
There is no shortage of opinions on this.

37
00:01:48,260 --> 00:01:50,550
Let me just pull out one
quote in particular.

38
00:01:50,550 --> 00:01:52,675
This is the WikiLeaks donations page.

39
00:01:52,675 --> 00:01:57,310
It says in plain and simple terms, Bitcoin
is a secure and anonymous currency.

40
00:01:58,350 --> 00:01:59,590
Is that actually true?

41
00:01:59,590 --> 00:02:03,080
Well, you'll also find a variety
of opinions to the contrary.

42
00:02:03,080 --> 00:02:04,940
Again, I'm just pulling out one example.

43
00:02:04,940 --> 00:02:07,420
This is the Wired UK saying,

44
00:02:07,420 --> 00:02:10,350
"Bitcoin won't hide you from
the NSA's prying eyes".

45
00:02:12,090 --> 00:02:15,450
So how can we resolve this confusion?

46
00:02:15,450 --> 00:02:17,970
Let's look at what
the word anonymous means.

47
00:02:17,970 --> 00:02:21,280
At quite a literal level,
anonymous means without a name.

48
00:02:21,280 --> 00:02:23,720
And so what does that mean exactly?

49
00:02:23,720 --> 00:02:25,920
Well there's two ways to interpret it.

50
00:02:25,920 --> 00:02:28,950
We know that in Bitcoin
addresses are public keys.

51
00:02:28,950 --> 00:02:32,010
You don't need to put in your real name
in order to interact with the system.

52
00:02:33,120 --> 00:02:36,440
Or public key hashes
instead of real identities.

53
00:02:36,440 --> 00:02:39,930
But we can interpret this
property of being without a name

54
00:02:39,930 --> 00:02:41,200
in two different ways.

55
00:02:41,200 --> 00:02:44,650
We could interpret it as interacting
without your real name or

56
00:02:44,650 --> 00:02:47,400
we can interpret it as interacting
without any name at all.

57
00:02:48,440 --> 00:02:51,160
Now, if you interpret it as
interacting without your real name,

58
00:02:51,160 --> 00:02:53,480
then certainly Bitcoin is
anonymous in that sense.

59
00:02:54,600 --> 00:02:57,119
But, we do have these public key hashes

60
00:02:58,190 --> 00:03:00,980
that act as some sort
of pseudo identities.

61
00:03:00,980 --> 00:03:03,550
And so when computer scientists
look at this situation,

62
00:03:03,550 --> 00:03:05,910
they don't use the term
anonymous to describe this.

63
00:03:05,910 --> 00:03:07,920
They call this pseudonymity.

64
00:03:07,920 --> 00:03:11,070
And there's a very clear
difference between the two, and

65
00:03:11,070 --> 00:03:13,229
it's an important one, and
we'll see why in a second.

66
00:03:14,470 --> 00:03:18,160
You might wonder, yeah, even though you're
using your pseudonym which is your public

67
00:03:18,160 --> 00:03:20,210
key hash you can create
any number of them.

68
00:03:20,210 --> 00:03:23,530
You can have as many
pseudonyms as you want.

69
00:03:23,530 --> 00:03:25,010
Does that make it anonymous?

70
00:03:25,010 --> 00:03:27,980
Well, the answer is not quite and
we'll get into that as well.

71
00:03:29,570 --> 00:03:33,610
Okay, so if computer scientists called
this pseudonymity, what is anonymity then?

72
00:03:33,610 --> 00:03:36,230
Is there a clear definition
of what it would take for

73
00:03:36,230 --> 00:03:38,210
something to be called anonymous?

74
00:03:38,210 --> 00:03:40,670
At a conceptual level
the answer is very simple.

75
00:03:40,670 --> 00:03:45,690
Anonymity in computer science is just
pseudonymity together with unlinkability.

76
00:03:47,170 --> 00:03:49,510
So, what is this property
called unlinkability?

77
00:03:49,510 --> 00:03:53,920
At an intuitive level we'll get into
better definitions in a little bit.

78
00:03:53,920 --> 00:03:58,660
But at an intuitive level,
what unlinkability means is that as a user

79
00:03:58,660 --> 00:04:03,510
interacts with the system repeatedly,
these different interactions should

80
00:04:03,510 --> 00:04:07,740
not be able to be tied to each other from
the point of view of some adversary.

81
00:04:07,740 --> 00:04:11,589
So you have to be talking about a specific
adversary for this to even make sense.

82
00:04:12,600 --> 00:04:18,420
Now, this distinction here between
full anonymity and mere pseudonymity

83
00:04:18,420 --> 00:04:22,500
is something that you might be familiar
with from a variety of other contexts.

84
00:04:22,500 --> 00:04:27,470
And one good way that I like to explain
this is to look at online forums.

85
00:04:27,470 --> 00:04:31,250
And again here the distinction between
a mere pseudonymous interaction and

86
00:04:31,250 --> 00:04:34,730
anonymous interaction comes
up in different forums.

87
00:04:34,730 --> 00:04:40,160
And Reddit is a good example of a forum
where you pick a long term pseudonym and

88
00:04:40,160 --> 00:04:42,510
then interact over a period
of time with that pseudonym.

89
00:04:42,510 --> 00:04:47,210
You could create different pseudonyms, but
it's going to be practically unfeasible

90
00:04:47,210 --> 00:04:51,130
to create a new pseudonym every single
time you want to post a comment.

91
00:04:51,130 --> 00:04:54,614
And it's not even very meaningful,
so Reddit offers to.

92
00:04:55,660 --> 00:04:59,600
The opposite of that, fully anonymous
interaction where you can make posts with

93
00:04:59,600 --> 00:05:03,360
no attribution at all, is the model
that you typically have in 4Chan.

94
00:05:04,620 --> 00:05:07,375
And there's a similar difference
in Bitcoin as well and

95
00:05:07,375 --> 00:05:11,190
Bitcoin is the pseudonymous model
more than the anonymous model.

96
00:05:11,190 --> 00:05:15,230
Okay, but let's talk about why this
difference is important in Bitcoin.

97
00:05:15,230 --> 00:05:19,440
Why is mere pseudonymity not
sufficient if you want privacy?

98
00:05:19,440 --> 00:05:23,760
After all, if you have pseudonymity,
it seems like even if somebody can

99
00:05:23,760 --> 00:05:27,950
create a pseudonymous profile of all
of your interactions on the system,

100
00:05:27,950 --> 00:05:29,890
they can't tie it back
to your real identity.

101
00:05:31,300 --> 00:05:33,900
Well, here's the answer to that.

102
00:05:33,900 --> 00:05:39,400
It turns out that if you have this
pseudonymous profile, it's pretty fragile.

103
00:05:39,400 --> 00:05:43,620
It's very easy for it to get linked back
to your real identity at some point.

104
00:05:43,620 --> 00:05:47,365
And if that happens at any point then,
of course, all of your transactions past,

105
00:05:47,365 --> 00:05:50,530
present, and
future have been linked to your identity.

106
00:05:50,530 --> 00:05:53,560
So here are a couple of different
ways in which that can happen.

107
00:05:53,560 --> 00:05:56,150
One is that a variety
of Bitcoin businesses,

108
00:05:56,150 --> 00:06:00,430
online wallet services,exchanges, and
others, even vendors in a lot of cases

109
00:06:00,430 --> 00:06:04,170
are going to want your real life identity
in order to let you transact with them.

110
00:06:05,200 --> 00:06:06,240
Consider this analogy.

111
00:06:06,240 --> 00:06:08,220
You go to a coffee shop.

112
00:06:08,220 --> 00:06:10,670
You pay for your coffee with Bitcoins.

113
00:06:10,670 --> 00:06:15,650
And of course if you are there in
the store then the person who's giving you

114
00:06:15,650 --> 00:06:20,160
your coffee sort of knows who you are,
even if they don't actually ask for

115
00:06:20,160 --> 00:06:21,220
your real name.

116
00:06:21,220 --> 00:06:26,650
And so your physical identity does get
tied to one of your Bitcoin transactions.

117
00:06:26,650 --> 00:06:30,670
And if that Bitcoin transaction then gets
tied to all of your Bitcoin transactions,

118
00:06:30,670 --> 00:06:33,680
then that is a complete
violation of anonymity.

119
00:06:33,680 --> 00:06:36,820
So this new issue of pseudonymous
profile is very fragile.

120
00:06:36,820 --> 00:06:40,030
It could easily get compromised
in a variety of ways.

121
00:06:40,030 --> 00:06:43,081
And also, even if such a direct
linkage doesn't happen,

122
00:06:43,081 --> 00:06:46,880
these linked profiles can be
deanonymized due to side channels.

123
00:06:46,880 --> 00:06:48,470
What do I mean by side channels?

124
00:06:48,470 --> 00:06:51,710
Well here's something that
I find intriguing that

125
00:06:51,710 --> 00:06:56,060
might seem like a tall claim, but in fact
such things have been known to happen.

126
00:06:56,060 --> 00:07:00,990
Maybe somebody looks at a profile of your
pseudonymous Bitcoin transactions and

127
00:07:00,990 --> 00:07:04,160
finds that you interact at
certain times of day and

128
00:07:04,160 --> 00:07:07,640
they are able to correlate the times
of day when you're active online

129
00:07:07,640 --> 00:07:11,640
with the times of day when your
Twitter account is posting tweets.

130
00:07:11,640 --> 00:07:15,850
And so they're able to find a connection
between your Twitter identity and

131
00:07:15,850 --> 00:07:17,810
your transactions on Bitcoin.

132
00:07:17,810 --> 00:07:19,770
Similar attacks have
been known to happen so

133
00:07:19,770 --> 00:07:24,510
this is why this notion of this anonymous
profile is considered fragile and for

134
00:07:24,510 --> 00:07:27,530
real anonymity we want the stronger
notion of unlinkability.

135
00:07:29,270 --> 00:07:32,180
So let's try to define it in a little
bit more concrete sense what

136
00:07:32,180 --> 00:07:34,680
unlinkability means in
the context of Bitcoin.

137
00:07:34,680 --> 00:07:37,430
We can do that in a variety
of different ways.

138
00:07:37,430 --> 00:07:40,980
One is that it should be hard to
link together different addresses of

139
00:07:40,980 --> 00:07:42,490
the same user.

140
00:07:42,490 --> 00:07:45,450
Another is that it should be hard to link
together different transactions made

141
00:07:45,450 --> 00:07:46,620
by the same user.

142
00:07:46,620 --> 00:07:48,120
Both of these seem intuitive.

143
00:07:48,120 --> 00:07:49,320
Look at this one though.

144
00:07:49,320 --> 00:07:53,075
It should be hard to link the sender
of a payment to its recipient.

145
00:07:53,075 --> 00:07:57,509
This one might sound a little confusing at
first because if you interpret a payment

146
00:07:57,509 --> 00:08:02,217
as a Bitcoin transaction, Then of course,
that transaction has inputs and outputs.

147
00:08:02,217 --> 00:08:03,356
And these inputs and

148
00:08:03,356 --> 00:08:08,370
outputs are inevitably going to be in the
blockchain publicly and linked together.

149
00:08:08,370 --> 00:08:12,480
And so you might think that this
is impossible to achieve, but

150
00:08:12,480 --> 00:08:16,070
if we interpret this notion of payment
in a different way, not as a single,

151
00:08:16,070 --> 00:08:20,490
direct BitCoin transaction, but
perhaps an indirect sort of payment

152
00:08:20,490 --> 00:08:23,370
that goes through a circuitous
route of transactions.

153
00:08:23,370 --> 00:08:27,980
Then one might imagine that the ultimate
sender and the ultimate recipient of that

154
00:08:27,980 --> 00:08:33,300
payment might not immediately be linkable,
looking at the Bitcoin blockchain.

155
00:08:33,300 --> 00:08:37,430
So these are all somewhat more concrete,
but still at an intuitive level,

156
00:08:37,430 --> 00:08:39,960
varieties of unlinkability that
one might want to shoot for.

157
00:08:41,680 --> 00:08:46,835
But if you look at this last definition it
might still be not entirely convincing.

158
00:08:46,835 --> 00:08:50,550
Let's say that you pay for
a particular product and

159
00:08:50,550 --> 00:08:54,210
it costs a certain amount of BitCoin and
then maybe you

160
00:08:54,210 --> 00:08:57,820
send that payment through a circuit right
of transactions but still you might think

161
00:08:57,820 --> 00:09:01,920
somebody looking at the blockchain
must be able to infer something.

162
00:09:01,920 --> 00:09:06,192
Specifically that Bitcoins left some
addresses a certain number of Bitcoins and

163
00:09:06,192 --> 00:09:08,720
Bitcoins showed up at some other address.

164
00:09:08,720 --> 00:09:12,300
And these two might be slightly different
because of transaction fees and so on, but

165
00:09:12,300 --> 00:09:13,680
roughly equal.

166
00:09:13,680 --> 00:09:18,460
And also roughly in the same time period
because there can't be too much of a lag

167
00:09:18,460 --> 00:09:21,822
between the sending and
the receiving of a payment.

168
00:09:22,840 --> 00:09:27,200
And so clearly even if we try to
achieve this kind of unlinkability,

169
00:09:27,200 --> 00:09:30,370
it can't be unlinkability between
all possible transactions,

170
00:09:30,370 --> 00:09:33,610
but some smaller subset of transactions
that look like each other.

171
00:09:34,840 --> 00:09:37,130
So let's make this a little
bit more concrete now.

172
00:09:37,130 --> 00:09:39,810
And this is how we quantify anonymity.

173
00:09:39,810 --> 00:09:43,410
We usually don't try to achieve
complete unlinkability.

174
00:09:43,410 --> 00:09:46,660
Which is unlinkability among
all possible transactions or

175
00:09:46,660 --> 00:09:50,830
addresses in the system, but
instead we go for something more measured.

176
00:09:50,830 --> 00:09:54,420
We try to maximize the size
of our anonymity set.

177
00:09:54,420 --> 00:09:58,440
The anonymity set is the size of
the crowd of other addresses or

178
00:09:58,440 --> 00:10:00,760
transactions that we're trying to hide in.

179
00:10:00,760 --> 00:10:04,330
So if I can be reasonably sure that
with respect to some adversary,

180
00:10:04,330 --> 00:10:07,110
there are these thousand other
transactions that look just like mine.

181
00:10:07,110 --> 00:10:09,490
And the adversary can't
tell which one was mine.

182
00:10:09,490 --> 00:10:12,580
And that we might consider to be
a pretty good level of anonymity.

183
00:10:15,100 --> 00:10:18,550
And to calculate this anonymity set,
it's not trivial at all.

184
00:10:18,550 --> 00:10:19,840
It takes a few steps.

185
00:10:19,840 --> 00:10:23,660
You have to first define concretely
what your adversary model is.

186
00:10:23,660 --> 00:10:26,410
And you have to reason carefully
about what that adversary knows,

187
00:10:26,410 --> 00:10:28,210
what they don't know, and
what they cannot know.

188
00:10:28,210 --> 00:10:31,470
And there's no general formula for
doing this.

189
00:10:31,470 --> 00:10:35,190
It requires carefully analyzing
each protocol and system, and

190
00:10:35,190 --> 00:10:36,560
doing it on a case by case basis.

191
00:10:37,890 --> 00:10:41,450
I want to point out that
in the Bitcoin community

192
00:10:41,450 --> 00:10:45,830
often people carry out intuitive
analyses of anonymity services.

193
00:10:45,830 --> 00:10:49,060
For example, mixing services that we're
going to see later in this lecture and

194
00:10:49,060 --> 00:10:51,600
often they come up with
ways like taint analysis.

195
00:10:51,600 --> 00:10:56,210
This is an intuitive way that tracks the
flow between a particular sending address

196
00:10:56,210 --> 00:10:58,060
and a particular receiving address.

197
00:10:58,060 --> 00:11:02,440
And intuitively it might make a lot
of sense, but if we consider it from

198
00:11:02,440 --> 00:11:06,540
the point of view of how we actually
should calculate anonymity, taint

199
00:11:06,540 --> 00:11:10,970
analysis is not a very good measure of
how much anonymity you get from a system.

200
00:11:10,970 --> 00:11:14,570
And the reason for
that is that it assumes a particular

201
00:11:14,570 --> 00:11:19,110
type of attack the adversary might
carry out, a rather naive attack.

202
00:11:19,110 --> 00:11:23,410
Looking directly for quantities of flow
between ascending and a receiving address.

203
00:11:23,410 --> 00:11:26,558
And if your adversary were
a little bit cleverer than that,

204
00:11:26,558 --> 00:11:30,440
then you might carry out taint analysis
and think that you have a lot of

205
00:11:30,440 --> 00:11:33,310
anonymity in a certain situation,
but in fact you might not.

206
00:11:34,430 --> 00:11:39,040
So, the bottom line from this slide
is that quantifying anonymity must

207
00:11:39,040 --> 00:11:42,880
be done in terms of the anonymity set, and
in some cases, probability distributions.

208
00:11:42,880 --> 00:11:44,680
On top of that anonymity set.

209
00:11:44,680 --> 00:11:48,220
And it requires a careful analysis
of the protocol in the system.

210
00:11:48,220 --> 00:11:50,570
You can't apply a simple formula.

211
00:11:50,570 --> 00:11:55,060
Okay, let's switch gears a little bit and
talk about the ethics of anonymity.

212
00:11:55,060 --> 00:11:56,880
Why do people want anonymity?

213
00:11:56,880 --> 00:11:59,560
We've already seen a little bit of
the connection between anonymity and

214
00:11:59,560 --> 00:12:02,350
privacy, but
let's make that very concrete?

215
00:12:02,350 --> 00:12:07,660
Now, in block chain based currencies
because all transactions are recorded

216
00:12:07,660 --> 00:12:11,654
on the ledger, they are totally and
publicly and permanently traceable so

217
00:12:11,654 --> 00:12:17,470
if your identity ever gets linked to
these transactions you are in a situation

218
00:12:17,470 --> 00:12:22,239
where your privacy level is much worse
then you get with traditional banking.

219
00:12:23,470 --> 00:12:25,600
Why?
Because anybody might be able to carry

220
00:12:25,600 --> 00:12:27,780
out this type of de-anonymization attack.

221
00:12:27,780 --> 00:12:29,360
Not specifically, a company or

222
00:12:29,360 --> 00:12:31,250
a government that you
might be worried about.

223
00:12:31,250 --> 00:12:32,690
Any member of the public.

224
00:12:32,690 --> 00:12:36,200
And your transactions,
since they're permanent.

225
00:12:36,200 --> 00:12:39,530
Your loss of anonymity years down the line
could affect all of your transactions

226
00:12:39,530 --> 00:12:40,574
today and vice-versa.

227
00:12:41,890 --> 00:12:45,680
So, we really want anonymity
to even get the privacy level

228
00:12:45,680 --> 00:12:50,500
of crypto-currencies to the level that
we enjoy with the traditional system.

229
00:12:50,500 --> 00:12:53,710
But also, people hope that it can
give us a new level of privacy.

230
00:12:55,130 --> 00:12:58,340
Of course, we have to acknowledge
the concerns as well, and one of the major

231
00:12:58,340 --> 00:13:01,349
concerns is money laundering, and all
of the bad things that that can enable.

232
00:13:02,490 --> 00:13:03,690
So let's talk about that.

233
00:13:03,690 --> 00:13:05,780
This is definitely a legitimate worry.

234
00:13:05,780 --> 00:13:09,670
I wouldn't be in favor of studying
anonymity in cryptic currencies, and

235
00:13:09,670 --> 00:13:12,940
ignoring the ethical aspects and saying,
oh that's not something I'm going to worry

236
00:13:12,940 --> 00:13:14,970
about, I'm only interested
in the technology.

237
00:13:14,970 --> 00:13:17,930
I think it's important to
consider the ethical aspects.

238
00:13:17,930 --> 00:13:20,850
There's one item of comfort
that I will offer, though.

239
00:13:22,070 --> 00:13:27,110
If you look at how things stand currently
in Bitcoin, the difficulty of things

240
00:13:27,110 --> 00:13:32,060
like money laundering is not necessarily
because the block chain is not so

241
00:13:32,060 --> 00:13:34,610
anonymous and so it's easy to trace flows.

242
00:13:34,610 --> 00:13:38,830
But, instead, the difficulty stems much
more from the fact that moving large flows

243
00:13:38,830 --> 00:13:43,940
into and out of the currency, rather than
within Bitcoin is what is really hard.

244
00:13:43,940 --> 00:13:45,760
In other words, cashing out is hard.

245
00:13:45,760 --> 00:13:48,950
And so, anti-money laundering efforts

246
00:13:48,950 --> 00:13:51,800
have great promise if they're
focused in this part of the system.

247
00:13:52,890 --> 00:13:57,030
And the good news is, that all of these
attempts to improve anonymity in BitCoin

248
00:13:57,030 --> 00:14:00,040
don't affect this part of
the equation in any way.

249
00:14:00,040 --> 00:14:04,460
And so, I would recommend that
BitCoin researchers and developers

250
00:14:04,460 --> 00:14:08,430
coordinate efforts with anti money
laundering efforts by law enforcement and

251
00:14:08,430 --> 00:14:12,980
others so that the technical
aspect of Bitcoin anonymity

252
00:14:12,980 --> 00:14:17,280
can be relatively separate from law
enforcement and legal aspects and so on.

253
00:14:19,240 --> 00:14:22,980
Nevertheless one could try to ask
can't we design the technology

254
00:14:22,980 --> 00:14:26,880
in such a way that only the good users
of Bitcoin anonymity are allowed and

255
00:14:26,880 --> 00:14:29,050
the bad users are somehow permitted.

256
00:14:29,050 --> 00:14:32,860
Well this turns out to be a quite common
conundrum is computer security and

257
00:14:32,860 --> 00:14:36,860
privacy and a lot of scenarios
we want something like this, but

258
00:14:36,860 --> 00:14:38,440
it never turns out to be possible.

259
00:14:38,440 --> 00:14:40,820
Why?
Because these different uses that we're

260
00:14:40,820 --> 00:14:44,400
talking about that we perceive
as being very different morally

261
00:14:44,400 --> 00:14:46,449
are going to be almost
identical technologically.

262
00:14:47,590 --> 00:14:50,750
And if we want to encode some sort
of moral rules into the technical

263
00:14:50,750 --> 00:14:55,450
rules of the system, that are going to
be automatically enforced by minors,

264
00:14:55,450 --> 00:14:56,750
it's not even clear how to do that.

265
00:14:56,750 --> 00:15:02,140
And so, hence my recommendation of
separating out the technical anonymity

266
00:15:02,140 --> 00:15:07,710
properties of the system, with the legal
principles that we put on top of it,

267
00:15:07,710 --> 00:15:09,840
in terms of how people use that currency.

268
00:15:11,420 --> 00:15:13,750
It's not a completely
satisfactory solution, but

269
00:15:13,750 --> 00:15:16,930
it's perhaps the best way we have of
trading off the good with the bad.

270
00:15:18,300 --> 00:15:21,970
I do want to point out that this is
far from the first time that we're

271
00:15:21,970 --> 00:15:22,890
considering this dilemma.

272
00:15:24,030 --> 00:15:28,029
It's come up in the context of Tor,
an anonymous communication network,

273
00:15:29,070 --> 00:15:33,440
and anonymous communication
enables bad actions,

274
00:15:33,440 --> 00:15:37,400
at least as much as anonymous
moving of funds does, and so

275
00:15:37,400 --> 00:15:41,540
Tor really had to grapple
with this problem.

276
00:15:41,540 --> 00:15:45,338
In a very simple and single picture
Tor as a communication network

277
00:15:45,338 --> 00:15:50,183
that routes messages between a sender and
a receiver, through a network of nodes.

278
00:15:50,183 --> 00:15:54,790
But further through some clever encryption
ensures that as long as at least some of

279
00:15:54,790 --> 00:15:56,926
the nodes in that network are honest,

280
00:15:56,926 --> 00:16:01,221
then the adversary is not going to be
able to link the sender to the receiver.

281
00:16:01,221 --> 00:16:06,130
So that's what Tor does, and you can see
how it can enable a lot of bad activities.

282
00:16:06,130 --> 00:16:09,880
Let's look at some activities good and
bad that do happen on the Tor network.

283
00:16:09,880 --> 00:16:14,230
It's used first of all by normal people
who want to protect themselves from

284
00:16:14,230 --> 00:16:16,000
being tracked online by marketers or

285
00:16:16,000 --> 00:16:18,969
various other privacy properties
online when they're browsing websites.

286
00:16:20,120 --> 00:16:23,676
It's used by journalists and activists and
dissidents and so on, and so

287
00:16:23,676 --> 00:16:25,950
that's clearly an important use case.

288
00:16:25,950 --> 00:16:27,270
It's also used by law enforcement.

289
00:16:28,440 --> 00:16:31,400
Because if they wanted to do
an electronic sting operation,

290
00:16:31,400 --> 00:16:35,480
then you want to be able to visit websites
without revealing that your IP address

291
00:16:35,480 --> 00:16:37,840
is coming from a law enforcement block.

292
00:16:37,840 --> 00:16:41,560
And so clearly a lot of activities
that we might approve of.

293
00:16:41,560 --> 00:16:44,570
But it's also used by botnets for
example, for

294
00:16:44,570 --> 00:16:48,020
spreading malware between
nodes in the network.

295
00:16:48,020 --> 00:16:51,040
And unfortunately there is also
child pornography in the network.

296
00:16:52,400 --> 00:16:56,730
So distinguishing between these uses at a
technical level is essentially impossible.

297
00:16:57,760 --> 00:17:00,860
And so Tor has grappled with
this issue and, as a society,

298
00:17:00,860 --> 00:17:02,450
we have grappled with it.

299
00:17:02,450 --> 00:17:05,000
And, by and large,
we've concluded that it's better for

300
00:17:05,000 --> 00:17:07,950
the world that the technology
exists than it doesn't.

301
00:17:07,950 --> 00:17:11,400
And, in fact, one of the main funders
of Tor is the US State Department.

302
00:17:11,400 --> 00:17:15,160
They're interested in it because Tor helps
dissidents in other countries who might be

303
00:17:15,160 --> 00:17:16,659
fighting oppressive governments and so on.

304
00:17:17,810 --> 00:17:22,580
And in fact recently, there was a news
story about the FBI having a successful

305
00:17:22,580 --> 00:17:27,460
string of sting operations against
people using Tor for child pornography.

306
00:17:27,460 --> 00:17:32,211
And so of course we have to remember
there is a level above the technology,

307
00:17:32,211 --> 00:17:37,271
that law enforcement can exploit a variety
of ways to get to people who are using

308
00:17:37,271 --> 00:17:41,975
these systems for bad purposes, and
so it preserves a sense of balance.

309
00:17:44,675 --> 00:17:47,380
So let's switch gears
a little bit once more.

310
00:17:47,380 --> 00:17:49,474
Let's look at the history
of anonymous e-cash.

311
00:17:51,020 --> 00:17:55,630
Even though with Bitcoin these
questions are quite controversial and

312
00:17:55,630 --> 00:17:59,200
there are debates about how
anonymous exactly Bitcoin is, and

313
00:17:59,200 --> 00:18:00,770
what are the options and so on.

314
00:18:00,770 --> 00:18:03,820
This is not the first time
that we have thought about

315
00:18:03,820 --> 00:18:06,740
anonymous cryptocurrencies
at a technical level.

316
00:18:06,740 --> 00:18:08,660
These efforts have quite a long history.

317
00:18:08,660 --> 00:18:11,858
In fact, all the way back in 1982,
more than two decades ago.

318
00:18:11,858 --> 00:18:15,880
Cryptographer David Chaum
proposed something called

319
00:18:15,880 --> 00:18:20,270
blind signatures that helped him
develop anonymous electronic cash.

320
00:18:21,340 --> 00:18:23,160
So what are blind signatures?

321
00:18:23,160 --> 00:18:26,018
Blind signatures are a two-party protocol.

322
00:18:26,018 --> 00:18:28,490
Two parties communicate
with each other and

323
00:18:28,490 --> 00:18:32,430
at the end of that,
one party has produced a digital signature

324
00:18:32,430 --> 00:18:35,450
of some input without actually
knowing what that input is.

325
00:18:36,550 --> 00:18:39,620
I know it sounds a little bit like magic
but I encourage you to look it up.

326
00:18:39,620 --> 00:18:42,120
It's not that sophisticated
at a technical level.

327
00:18:42,120 --> 00:18:45,990
It's quite simple to understand
if you work through the details.

328
00:18:45,990 --> 00:18:50,620
But since I'm not actually going to
go into the details now, let's for

329
00:18:50,620 --> 00:18:52,529
the moment assume that
this works by magic.

330
00:18:53,680 --> 00:18:56,950
So assuming that we have line signatures,

331
00:18:56,950 --> 00:19:00,380
how can that help us achieve
an electronic cache protocol?

332
00:19:00,380 --> 00:19:02,690
That's what David Chaum did and

333
00:19:02,690 --> 00:19:05,760
as we go through this protocol
try to see if you can

334
00:19:05,760 --> 00:19:10,440
spot any other flaws with it other than
the anonymity properties or lack there of.

335
00:19:10,440 --> 00:19:14,339
It's quite a simple protocol and I'm going
to show it to you in just one slide.

336
00:19:15,680 --> 00:19:18,970
Now imagine that there is a bank and
this is a protocol for

337
00:19:18,970 --> 00:19:22,080
anonymous e-cash through blind signatures.

338
00:19:22,080 --> 00:19:26,550
Imagine that there is a bank and the bank
stores various things in its database.

339
00:19:26,550 --> 00:19:29,110
In particular it stores these two tables.

340
00:19:29,110 --> 00:19:32,370
The first table has a mapping of users

341
00:19:32,370 --> 00:19:34,719
with the balance that they
have in their bank account.

342
00:19:35,930 --> 00:19:39,290
These balances don't refer to any
sort of cryptographic currency.

343
00:19:39,290 --> 00:19:42,030
It's just a plain old number
sitting in a database,

344
00:19:42,030 --> 00:19:44,680
just like your actual bank account or
PayPal or something like that.

345
00:19:46,160 --> 00:19:49,010
In addition,
it has another table called spent coins.

346
00:19:49,010 --> 00:19:50,344
And you'll see in
a moment what this means.

347
00:19:52,621 --> 00:19:56,526
Let's say that a user now wants to
withdraw an anonymous coin from

348
00:19:56,526 --> 00:19:58,040
the system.

349
00:19:58,040 --> 00:20:00,220
And now this is where
the cryptomagic is going to come in.

350
00:20:01,390 --> 00:20:05,610
So, the user wishes to withdraw an
anonymous coin of a standard denomination.

351
00:20:05,610 --> 00:20:10,330
Let's say that's one dollar denomination
and all of these values refer to dollars.

352
00:20:10,330 --> 00:20:14,000
So, the first thing that the bank is
going to do on receiving this request

353
00:20:14,000 --> 00:20:15,990
is deduct this user's balance.

354
00:20:15,990 --> 00:20:18,880
It's gone down from ten
to nine in this example.

355
00:20:18,880 --> 00:20:20,070
The next thing the user and

356
00:20:20,070 --> 00:20:24,290
the bank are going to do together
is execute a two-party protocol.

357
00:20:24,290 --> 00:20:28,740
A blind signature protocol,
at the end of which the user,

358
00:20:28,740 --> 00:20:31,440
having picked a random
serial number of a coin.

359
00:20:31,440 --> 00:20:33,350
That's what's being depicted here.

360
00:20:33,350 --> 00:20:35,960
This is the serial number for
an anonymous coin, and

361
00:20:35,960 --> 00:20:38,730
the user was completely at
liberty to pick that number.

362
00:20:38,730 --> 00:20:41,240
She did, and
then they executed a protocol,

363
00:20:41,240 --> 00:20:46,690
at the end of which the user has received
a signature of this serial number, but

364
00:20:46,690 --> 00:20:50,440
in such a way that the bank did not,
in fact, learn the serial number.

365
00:20:50,440 --> 00:20:52,708
The bank had no idea what
number it was signing,

366
00:20:52,708 --> 00:20:55,158
it just knew that it was
some number that it signed.

367
00:20:57,941 --> 00:21:03,490
And now this signed number
represents an anonymous token.

368
00:21:03,490 --> 00:21:07,140
This is a token that the user
can pass around to another user.

369
00:21:07,140 --> 00:21:10,800
So, let's say that she wants to
make a payment to another user.

370
00:21:10,800 --> 00:21:15,600
What she'll do is send to that
user not only the signed token but

371
00:21:15,600 --> 00:21:18,479
also the plain text value of
the token of the serial number.

372
00:21:20,040 --> 00:21:24,660
And what the receiving user will
do immediately is the following.

373
00:21:24,660 --> 00:21:29,460
She will immediately contact the bank and
try to deposit this anonymous coin.

374
00:21:30,740 --> 00:21:35,510
Because without actually trying
to deposit it this red user here

375
00:21:35,510 --> 00:21:39,210
cannot be sure that this blue user
is not trying to double spend.

376
00:21:39,210 --> 00:21:43,640
The blue user could be sending that same
anonymous coin to 100 different users.

377
00:21:43,640 --> 00:21:46,280
How can they know that
they're not being tricked

378
00:21:46,280 --> 00:21:48,220
into accepting a double-spent coin?

379
00:21:48,220 --> 00:21:51,910
The way they're sure is when
the red user receives the coin,

380
00:21:51,910 --> 00:21:55,350
they have to immediately contact
the bank to verify if it's valid or not.

381
00:21:57,240 --> 00:22:00,990
And only if the coin turns out to be valid
will the red user proceed to complete

382
00:22:00,990 --> 00:22:03,989
the rest of whatever transaction
she was having with the blue user.

383
00:22:05,860 --> 00:22:08,990
So the bank now receives
the message to deposit the coin.

384
00:22:08,990 --> 00:22:10,930
And note that it now gets, finally,

385
00:22:10,930 --> 00:22:14,840
the plaintext serial number,
as well as its own signature.

386
00:22:14,840 --> 00:22:19,630
The bank looks at the signature,
verifies that it's a valid signature.

387
00:22:19,630 --> 00:22:23,960
And here's the key thing, it also verifies
that the serial number it received

388
00:22:23,960 --> 00:22:26,470
is not on the list of spent coins.

389
00:22:26,470 --> 00:22:29,590
That's how it knows that this
is not a doubles bin attempt.

390
00:22:29,590 --> 00:22:34,710
This is the legitimate first spend of
the coin that the bank signed before.

391
00:22:34,710 --> 00:22:36,380
So it's a legitimate, anonymous token.

392
00:22:39,060 --> 00:22:42,470
Since the bank didn't see the serial
number the first time around,

393
00:22:42,470 --> 00:22:48,170
the bank does not know which user
initially withdrew this anonymous coin.

394
00:22:48,170 --> 00:22:49,750
And that's the key anonymity property.

395
00:22:50,960 --> 00:22:54,790
In the period of time between the blue
user withdrawing this coin and then,

396
00:22:54,790 --> 00:22:59,190
perhaps much later, sending it to the red
user who immediately deposits the coin,

397
00:22:59,190 --> 00:23:03,680
many other pairs of users might have
deposited and withdrawn coins, and

398
00:23:03,680 --> 00:23:05,269
the bank has no way to tell them apart.

399
00:23:08,120 --> 00:23:11,920
So coming back to this part of
the protocol, the bank verifies that this

400
00:23:11,920 --> 00:23:15,500
is a new serial number that
it's seeing for the first time.

401
00:23:15,500 --> 00:23:18,460
It puts that serial number into
its list of spent coins so

402
00:23:18,460 --> 00:23:23,390
that it cannot be spent anymore,
and adds one dollar, or

403
00:23:23,390 --> 00:23:26,690
whatever the denomination is,
to red's account.

404
00:23:26,690 --> 00:23:28,940
And then sends back a message
saying this is okay.

405
00:23:30,140 --> 00:23:35,080
And now the red user has verified
that they received a legitimate

406
00:23:35,080 --> 00:23:39,820
anonymous coin from the blue user, and can
now proceed to complete the transaction.

407
00:23:41,750 --> 00:23:46,730
So this is the entirety of a very simple
anonymous electronic cash scheme, and

408
00:23:46,730 --> 00:23:50,559
the key property here is that
the bank cannot link the two users.

409
00:23:52,650 --> 00:23:56,900
So I asked you to think about whether this
has any drawbacks, other than anonymity.

410
00:23:56,900 --> 00:23:59,720
And of course, the glaring
thing that you probably noticed

411
00:23:59,720 --> 00:24:03,280
is that all of this depends
upon trusting this bank.

412
00:24:03,280 --> 00:24:05,080
I mean, look at this part of the system.

413
00:24:05,080 --> 00:24:10,680
This is simply the bank keeping numbers in
its database of who owns how much money.

414
00:24:10,680 --> 00:24:13,530
Right.
So this seems to be a trust model that's

415
00:24:13,530 --> 00:24:17,010
very, very different from the model
that Bitcoin operates under.

416
00:24:18,310 --> 00:24:21,400
So a lot of the traditional
cryptography research on

417
00:24:21,400 --> 00:24:23,480
anonymous e-cash was in this model,

418
00:24:23,480 --> 00:24:27,910
where you were willing to trust a bank for
many things, including keeping your money.

419
00:24:27,910 --> 00:24:32,070
But you were not willing to
trust a bank without anonymity.

420
00:24:32,070 --> 00:24:36,360
You wanted to be sure that the bank
didn't know who was interacting with who.

421
00:24:36,360 --> 00:24:39,020
Okay, it's an interesting model.

422
00:24:39,020 --> 00:24:40,190
It's a valid model.

423
00:24:40,190 --> 00:24:44,850
And many such schemes were
developed under this model.

424
00:24:44,850 --> 00:24:49,920
But in retrospect, it seems to have
been that the decentralization problem

425
00:24:49,920 --> 00:24:54,370
was a much more important one to solve
than the anonymity problem in order for

426
00:24:54,370 --> 00:24:57,770
anonymous, electronic cash
to become successful.

427
00:24:57,770 --> 00:25:00,585
People were willing to
attempt a decentralized,

428
00:25:00,585 --> 00:25:03,450
de-cashed system with only sort of
pseudo anonymity properties and

429
00:25:03,450 --> 00:25:07,640
not real anonymity and then get to
work on maybe approving the anonymity.

430
00:25:07,640 --> 00:25:12,670
Instead of starting from a fully provably
anonymous electronic cash system

431
00:25:12,670 --> 00:25:15,110
that relied on a single,
central authority.

432
00:25:17,190 --> 00:25:21,130
But more generally,
anonymization and decentralization,

433
00:25:21,130 --> 00:25:25,580
as we'll see repeatedly in this lecture,
are in conflict with each other.

434
00:25:25,580 --> 00:25:27,558
There are at least a couple of reasons for
this.

435
00:25:27,558 --> 00:25:30,840
One is that,
as we saw in the last slide, opting for

436
00:25:30,840 --> 00:25:35,710
anonymity, you might want to rely on
certain interactive protocols with a bank

437
00:25:35,710 --> 00:25:40,170
in order to do some blinding,
which we saw in blind signatures.

438
00:25:40,170 --> 00:25:42,430
That's where you get anonymity from.

439
00:25:42,430 --> 00:25:45,300
But how are you going to do that without
a central bank to carry out that

440
00:25:45,300 --> 00:25:46,070
protocol with.

441
00:25:46,070 --> 00:25:46,660
It's not clear.

442
00:25:48,250 --> 00:25:50,500
But even if you got rid
of this blinding and

443
00:25:50,500 --> 00:25:54,150
were willing to accept just
pseudonymity instead of true anonymity.

444
00:25:54,150 --> 00:25:58,330
You still have the problem that in order
to decentralize and still get security

445
00:25:58,330 --> 00:26:02,610
properties like resistance to double
spending, often the way to go

446
00:26:02,610 --> 00:26:06,410
is to record and trace everything
in a public ledger as BitCoin does.

447
00:26:07,420 --> 00:26:12,370
And so you might even further compromise
your anonymity and privacy properties.

448
00:26:12,370 --> 00:26:15,480
So these are two big
challenges to overcome.

449
00:26:15,480 --> 00:26:18,730
And as we'll see much later in
this lecture, as zero coin and

450
00:26:18,730 --> 00:26:21,580
zero cash are cryptographic, anonymous,

451
00:26:21,580 --> 00:26:25,960
decentralized electronic cash schemes,
that have some

452
00:26:25,960 --> 00:26:30,570
similarities to the blind signature based
protocol that I showed you earlier.

453
00:26:30,570 --> 00:26:34,025
But some of the giant challenges that
they have to tackle involve these two

454
00:26:34,025 --> 00:26:34,755
limitations.

